Product privacy notice
This notice explains who is responsible for personal data when an organisation uses Axera’s ERP, WMS and CRM product, what the product can process, and where people should direct privacy requests.
Decides why ERP data is used, what is entered and who may access it.
Processes customer data to provide the service and follow documented instructions.
Last updated: 23 August 2026
Our respective roles
Axera is a trading name of EJ Global Limited, company number 17231331, registered in England and Wales. This notice applies to Axera’s hosted ERP, warehouse management and CRM service.
The customer is normally the controller
The organisation subscribing to Axera normally decides why and how personal data in its workspace is used. This can include data about its workers, customers, suppliers, prospects, drivers and other business contacts. The customer is responsible for having a lawful basis, giving required privacy information, configuring appropriate access and responding to individuals’ rights.
Axera is normally the processor
Axera processes that customer-controlled data on the customer’s behalf to host, operate, secure, maintain and support the service. We follow the customer’s documented instructions, the customer agreement and the applicable data-processing terms, unless UK law requires otherwise.
The role depends on the purpose of a particular activity, not only the label in a contract. Axera can be a processor for ERP records and a controller for separate information it needs for its own business purposes.
This notice summarises those roles. A separate written Data Processing Addendum should accompany the customer agreement and set the binding processing instructions and Article 28 responsibilities.
Data the product can handle
The exact information depends on which modules and fields the customer chooses to use. It can include:
Users and access
Names, work contact details, job titles, departments, roles, permissions, account status, supplier-portal links and authentication or security settings.
Business contacts
Customer, supplier, prospect and contact names, business addresses, email addresses, telephone numbers, job information, notes and communication preferences.
Orders and warehouse operations
Orders, purchase orders, delivery details, bookings, stock and picking movements, returns, vehicles, location activity, barcodes and records of who performed an action.
Finance and commercial records
Invoices, transactions, payment status, credit information, quotations, proposals, pricing, billing references and supporting documents uploaded by authorised users.
Tasks, support and content
Tasks, comments, notifications, support tickets, guided-help feedback, messages, notes and files that users choose to upload.
Audit and technical records
Stock and finance audit trails, user-attributed changes, feature usage, request and diagnostic identifiers, IP-derived security controls, errors and other service logs.
The data normally comes from the customer and its authorised users, is generated through their use of the product, or is imported through an integration the customer chooses to configure. Customers should not enter special-category or criminal-offence data unless its use has been agreed, is lawful and appropriate safeguards are in place.
How Axera processes customer-controlled data
As processor, we use customer-controlled data only as needed to:
- provide the ERP, WMS, CRM, finance, reporting and related features selected by the customer;
- authenticate users and apply the customer’s roles and permissions;
- host, store, back up, transmit and retrieve information;
- provide requested implementation, maintenance, troubleshooting and support;
- protect the service, investigate incidents and prevent misuse; and
- comply with documented instructions or a legal requirement that applies to us.
We do not sell, rent or trade customer-controlled data. We do not use it for third-party advertising or to build advertising profiles, and we do not use it to train our own general-purpose AI models.
Axera does not determine the customer’s lawful basis for ordinary ERP processing. The customer must identify and document the appropriate basis for its own purposes and use of the product.
When Axera acts as a controller
Axera acts as a separate controller where we decide an independent business purpose for limited personal information. Depending on the relationship, this can include:
- customer representatives and commercial contacts used to administer contracts, accounts and billing;
- support correspondence and service communications with people who contact us directly;
- security, authentication, abuse-prevention and diagnostic records needed to protect the platform;
- records needed to establish or defend legal claims or meet accounting and regulatory obligations; and
- service and AI-usage records, including the user, feature, model, token totals and estimated cost, used to operate, control and account for enabled features.
Our usual lawful bases for these activities are performance of a contract, our legitimate interests in administering and securing the service, and compliance with legal obligations. We retain this information only for as long as needed for those purposes and applicable record-keeping requirements.
Public website visits, demo enquiries and prospect communications are covered separately by our website privacy notice.
Service providers, integrations and AI
We may use contracted service providers for infrastructure, database hosting, backups, security, monitoring, support and email delivery. Where they handle customer-controlled data, they act as subprocessors and are subject to data-protection obligations. The applicable Data Processing Addendum should identify the current subprocessor information and any notification process for changes.
Optional OpenAI features
AI features remain unavailable unless an organisation enables them and configures an API key. An explicit user action may then send a bounded prompt and relevant, permission-scoped context to the configured OpenAI API. Axera records feature, model and usage totals for control and accounting. We do not make automatic per-keystroke or background OpenAI calls.
Optional email delivery
If a customer configures Mailgun-backed marketing features, recipient addresses, message content and delivery events may be sent to or received from Mailgun to deliver mail and enforce suppression, opt-out and bounce rules. Sending remains under customer configuration and authorised user actions.
A customer may also configure its own integrations. That customer is responsible for assessing the integration, authorising the transfer and informing affected individuals. Some providers may process information outside the United Kingdom; where we arrange such a transfer, we use an applicable lawful mechanism and safeguards.
Security, permissions and human access
We use technical and organisational measures appropriate to the service and risk. These include authenticated access, customer-configured roles and permissions, protected credentials and secrets, encrypted transport, audit trails for material operations, rate limiting, backups and diagnostic monitoring.
Customer data is available to the customer’s authorised users according to their permissions. Axera personnel may access it only where needed to provide requested support, operate or secure the service, comply with law, or otherwise follow documented customer instructions. Personnel with access are subject to confidentiality obligations.
No system can guarantee absolute security. Customers must manage their user accounts, permissions, devices and authentication methods appropriately and notify us promptly of suspected compromise.
Retention, return and deletion
The customer controls how long its operational records are required, subject to product capabilities, the customer agreement, documented instructions and applicable law. Some stock, finance and other audit records are intentionally preserved to maintain an accurate history and should not be altered or removed without a lawful, authorised process.
At the end of the service, return and deletion of customer-controlled personal data should be handled under the Data Processing Addendum and the customer’s instructions. Copies may remain temporarily in protected backups until they age out through the normal backup cycle, or longer where UK law requires retention.
Axera-controlled commercial, security, support and legal records follow retention periods based on their purpose, risk and applicable limitation or record-keeping requirements. Data that is no longer required is deleted or anonymised.
Individual rights and requests
For data in a customer workspace
Contact the organisation that provided your account, employs you, or entered your information into Axera. It is normally the controller and decides how to respond. If you contact Axera about customer- controlled data, we will normally refer or pass the request to the relevant customer and assist it as required by our processing terms.
For data controlled by Axera
Contact hello@axera.uk. Depending on the circumstances, you may have rights of access, correction, erasure, restriction, objection and portability. These rights are not absolute, and we may need to confirm your identity.
Axera’s AI features provide advisory, search or drafting assistance and do not make solely automated decisions about individuals that produce legal or similarly significant effects. Operational changes remain subject to authorised user action and server-side controls.
Contact, complaints and changes
For product privacy questions, contact EJ Global Limited, trading as Axera, at hello@axera.uk. Customer administrators can also use their usual Axera support route for contractual or processing questions.
If Axera is the controller for the matter, you may complain to the UK Information Commissioner’s Office. Current guidance is available on the ICO website. Where the customer is controller, you may also raise the matter with that organisation or its relevant supervisory authority.
We may update this notice when the service, providers or processing arrangements change. The date at the top identifies the current version.